|
1.
µé¾î°¡±â ¾Õ¼
Linux°¡
Áß¼ÒÇü ³×Æ®¿öÅ© ȯ°æ¿¡¼ ÈǸ¢ÇÏ°Ô ÀÛµ¿ÇÏ´Â °ÍÀº ¸®´ª½º¸¦ »ç¿ëÇϰí ÀÖÁö
¾ÊÀº »ç¶÷µµ ÀÍÈ÷ µé¾î ¾Ë°í ÀÖ°ÚÁö¸¸ ½ÇÁ¦ ¹®¼ÀڷḦ ¾Æ¹«¸® ã¾ÆºÁµµ ¸Ó½ºÄ¿·¹À̵ù
¹æ½ÄÀ» ÀÌ¿ëÇÑ ¹æÈº® ±¸¼º¿¡ ´ëÇÑ ±Û¸¸ ÀÖÀ» »Ó ÀÌ¹Ì ±¸¼ºµÈ ½ÇÁ¦ IP¸¦
°¡Áö´Â ³×Æ®¿÷¿¡¼ ¹æÈº® ¹× Æ÷¿öµù ¸Ó½ÅÀ» ±¸ÃàÇÏ´Â °Í¿¡ ´ëÇØ¼´Â ÀÚ·á°¡
ºÎÁ·ÇÏ¿© º»ÀÎÀº ÀÌ·¸°Ô Mini-HOWTO¸¦ °¨È÷ ¾²°Ô µÇ¾ú´Ù.
2.
¿ä±¸»çÇ×
-
°£´ÜÇÑ ³×Æ®¿öÅ© °³³ä(routing , netmask , forwarding,
etc.)
- ½ÇÁ¦ Router¶û ¿¬°áµÇ¾î Àְųª Wan Ä«µå°¡ ºÎÂøµÈ ¸®´ª½º ¸Ó½®
- ´ã¹è(ºñ Èí¿¬ÀÚ´Â Äݶó)
3.
º»ÀÎÀÇ Àåºñ ¹× ȯ°æ
-
Router: CISCO 4500M + 1 Fastethernet module
+ 4 serial module
- CSU : º¸¶ó³Ý ÀÓ´ë Àåºñ
- Linux1: Intel pentium III 500 + 128M ram
+ 9G HDD
- NIC: 3com 905 , 905b
- HUB: Intel 405T standalone switch HUB
* 3
- IP´ë¿ª: 211.50.38.0/25 (255.255.255.128)
- µð½º ÇѺ¸·ç + ÁöÆ÷ ¶óÀÌÅÍ
- Network Bandwidth: T1
4.
³ë°¡´Ù ½ÃÀÛ
¿ì¼±
ÀÚ½ÅÀÇ ¶ó¿ìÅͳª ·£Ä«µå¿¡ ¸Â´Â Å©·Î½º ÄÉÀ̺íÀ» ¸¸µç´Ù. Å©·Î½º ÄÉÀ̺íÀ»
¸¸µé ÁÙ ¸ð¸£´Â »ç¶÷Àº ÀßÇÏ´Â »ç¶÷¿¡°Ô ¹è¿ì°Å³ª ÀÎÅͳݿ¡¼ °Ë»öÇØº»´Ù.
¾Æ´Ï¸é ¿ë»êÀ̳ª Å×Å©³ë¸¶Æ® µîÁö¿¡¼ Å©·Î½º µÈ ¶óÀÎÀ» »ç´øÁö Å©·Î½º¸¦ ½ÃÄÑÁÖ´Â
ÀèÀ» »ç¸é µÈ´Ù. Áß¿äÇÑ °ÍÀº ÀÌ¹Ì ±¸¼º µÇÀÖ´Â ³×Æ®¿÷¿¡ ¸®´ª½º ¹Ú½º¸¦
Ãß°¡ÇÔÀ¸·Î¼ ¹æÈº® ¹× Æ÷¿öµù±â´ÉÀ» Á¦°øÇÏ´Â °ÍÀ̱⠶§¹®¿¡ ±âÁ¸ ¶ó¿ìÅÍ¿¡¼
Çãºê·Î ¿¬°áµÇ´Â ¶óÀÎÀ» Áß°£¿¡¼ °¡·Îä¾ß¸¸ ÇÑ´Ù. ±×¸²À¸·Î µµ½ÄÇØº¸°Ú´Ù.
Cross
Line(ƯÁ¤ Çãºê´Â Direct¸¦ ½áµµ µÊ)
------------
PC
------------
PC
------------
PC
------------
PC
Router Hub
[±×¸².1]
¿ø·¡ »óÅÂ
Cross
------------
PC |
------------
PC
------------
PC
------------
PC
Router Box
Hub
[±×¸².2] Linux
Box°¡ Ãß°¡µÈ »óÅÂ
±×·³
Áß°£¿¡¼ °¡·Îä±â¸¸ ÇÏ¸é µÇ´À³Ä? Àý´ë·Î µÉ¸®°¡ ¾øÀ» °ÍÀÌ´Ù. :) ¿ì¼±
¸®´ª½º¹Ú½ºÀÇ ¼¼ÆÃºÎÅÍ ÇØº¸ÀÚ. ÆíÀǸ¦ À§ÇØ º»ÀÎÀÇ ½ÇÁ¦ IP¸¦ »ç¿ëÇϰڴÙ.
Âø¿À¾ø±â ¹Ù¶õ´Ù. Áß¿äÇÑ°Ç ¸®´ª½º ¹Ú½º¿¡ ·£Ä«µå µÎÀåÀÌ»óÀÌ ºÙ¾î ÀÖ¾î¾ß
ÇÑ´Ù´Â °ÍÀÌ´Ù. ±×¸®°í Æ÷¿öµù½Ã ½Å·Ú¼º°ú ¼Óµµ¸¦ À§ÇØ ¹ö½º ¸¶½ºÅ͸µÀÌ ÀߵǴÂ
100Mbps PCI ·£Ä«µå¸¦ »ç¿ëÇϱ⸦ ±ÇÀåÇÑ´Ù. 3ComÀ̳ª IntelÀÇ
100Mbps ·£Ä«µå¶ó¸é ¹«³ÇÒ °ÍÀÌ´Ù.
¿©±â¼´Â
3Com 3c905¿Í 905b¸¦ »ç¿ëÇÑ´Ù. Çϵå¿þ¾îÀûÀÎ Áغñ°¡ ³¡³µÀ¸¸é
Ä¿³Î ÄÄÆÄÀÏÀ» ÇÑ´Ù. ³×Æ®¿÷ ºÎºÐ¿¡¼ ²À IP_FORWARDINGÀ» ¼³Á¤Çؾß
ÇÑ´Ù. ipchains »ç¿ëÀ» À§ÇØ IP_FIREWALLÀ» ¼³Á¤ÇÏ´Â °Íµµ
²À ÀØÁö ¸»ÀÚ. ÀÌ·¸°Ô ¸¸Àº Ä¿³Î·Î ÀçºÎÆÃ ÈÄ ·£Ä«µå°¡ Àß Àνĵȴٸé ÀÌÁ¦´Â
¾à°£ÀÇ ÀÛ¾÷ÀÌ ÇÊ¿äÇÏ´Ù. ¿ì¼± ¶ó¿ìÅÍ¿Í ¹Ù·Î ¹°¸° ·£Ä«µåÀÇ µð¹ÙÀ̽º¸¦ ¾Ë¾Æ¾ß
ÇÑ´Ù(º»ÀÎÀº eth1). ÀÌÁ¦ ´ÙÀ½ºÎÅͰ¡ Áß¿äÇѵ¥ ¼ö¸¹Àº ½ÃÇàÂø¿À ³¡¿¡
¾òÀº °á·ÐÀ» ¸»ÇÏÀÚ¸é ¶ó¿ìÅÍÀÇ IP¿Í ¸®´ª½ºÀÇ ¶ó¿ìÅÍ¿Í ¹°¸° ·£Ä«µå IP¸¦
private IP - Áï, ½ÇÁ¦·Î ¶ó¿ìÆÃ¿ëÀ¸·Î »ç¿ëÇÏÁö ¾Ê´Â »ç¼³ ¸Á
¿ë IP - ·Î ¹èÁ¤ÇØ¾ß ÇÑ´Ù´Â °ÍÀÌ´Ù. º»ÀÎÀº Router¿¡´Â 10.0.0.1À»
eth1¿¡´Â 10.0.0.2¸¦ ¹èÁ¤Çß´Ù.
½ÇÁ¦
IP¸¦ ¶ó¿ìÅÍ¿Í ·£Ä«µå¿¡ ¹èÁ¤À» ÇÒ °æ¿ì¿¡´Â ¼ºê³ÝÀ¸·Î ´Ù½Ã ³ª´©Áö ¾ÊÀº
³×Æ®¿÷ÀÇ °æ¿ì(Áï 211.50.38.0/128À» ´Ù½Ã ´õ ³ª´©Áö
¾Ê´Â ÀÌ»ó) ¶ó¿ìÅÍ¿¡¼ ¶ó¿ìÆÃÀ» Á¦´ë·Î ÇØÁÙ ¼ö°¡ ¾ø±â ¶§¹®¿¡ µÎ ÀåÄ¡¿¡´Â
¶ó¿ìÆÃÀÇ º¸ÁõÀ» À§ÇØ »ç¼³ IP¸¦ »ç¿ëÇÑ °ÍÀÌ´Ù. ½ÇÁ¦ ÀÌ·± ¹®Á¦ ¶§¹®ÀÎÁö
ISP¿¡¼´Â ½Ã¸®¾ó(¶ó¿ìÅͰ£ Åë½Å IP)¿¡´Â netmask 255.255.255.252¸¦
»ç¿ëÇÑ´Ù. IP¸¦ ¹èÁ¤ÇÑ ´ÙÀ½ ³ª¸ÓÁö´Â ±×´ÙÁö Áß¿äÇÑ°Ô ¾ø´Ù. ÀÌ ±ÛÀÇ
¸ñÀûÀÌ ¿ø·¡ Á¸ÀçÇÏ´Â ³×Æ®¿÷¿¡ ¿µÇâÀ» ¹ÌÄ¡Áö ¾Ê°í Á¶¿ëÈ÷ ¸®´ª½º¸¦ Áý¾î
³Ö´Â °ÍÀ̱⠶§¹®¿¡ ³ª¸ÓÁö ·£Ä«µå¿¡´Â ¿ø·¡ ¶ó¿ìÅͰ¡ ¾²´ø IP(ÀϹÝÀûÀ¸·Î
°ÔÀÌÆ®¿þÀÌ IP)¸¦ ¹èÁ¤ÇÑ´Ù.
Network:
211.50.38.0/25
Cross
--------
PC 211.50.38.2|
--------
PC 211.50.38.3
--------
PC 211.50.38.4
--------
PC
¶ó¿ìÅÍ ¸®´ª½º
Çãºê
(¶ó¿ìÅÍ)
(¸®´ª½º)
serial: NIC0:
211.50.1.202/30
10.0.0.2
·£ NIC1:
10.0.0.1 211.50.38.1
ÀÏ´Ü
ÀÌ·¸°Ô ±¸¼ºÀÌ µÇ¸é IP_FORWARDINGÀÌ ¾Ë¾Æ¼ ÀÌ·ç¾îÁö±â ¶§¹®¿¡
ÇãºêÂÊ¿¡ ¹°¸° PC¿¡¼ ¿ÜºÎ·Î ³ª°¡´Â ³×Æ®¿÷À» ¾µ °æ¿ì ¹«Á¶°Ç ¿ì¸®°¡ ¸¸µç
¸®´ª½º Æ÷¿öµù ¸Ó½®À» Áö³ª°¡°Ô µÈ´Ù. ÀÚ ÀÌÁ¦´Â Æ÷¿öµù ¸Ó½®¿¡¼ ipchains¸¦
ÀÌ¿ëÇØ °¢Á¾ ¹æÈº® ¼³Á¤À» ÇÒ ¼ö ÀÖ´Ù. ȸ»ç ³»ºÎ¿¡¼ ¾÷¹«½Ã°£ Áß Ã¤ÆÃÀ»
¸·±â À§ÇØ irc Æ÷Æ®·Î ³ª°¡´Â ¸ðµç ³×Æ®¿÷À» ¸·À» ¼öµµ ÀÖÀ» °ÍÀ̰í ,
Áö±Ý Ȱ¼ºÈµÈ ³×Æ®¿÷À» ²÷À» ¼öµµ ÀÖ´Ù :) ½Ç·Ê¸¦ À§ÇØ º»ÀÎÀÇ ¼³Á¤ ¸î
°¡Áö¸¦ º¸À̰ڴÙ.
-
¶ó¿ìÅÍ ¼³Á¤
|
[root@unixian
/root]# ztelnet 10.0.0.1
Trying 10.0.0.1...
Connected to 10.0.0.1.
Escape character is ¡®^]¡¯.
WyzSoft Research & Development
Lab. Access-control Router
User Access
Verification
Password: router>en
Password: router#show running-config
Building configuration...
Current configuration:
!
version 11.2
no service password-encryption
no service udp-small-servers
no service tcp-small-servers
!
hostname router
!
enable secret 5 ******************************
!
ip subnet-zero
ip domain-name wyzlab.com
ip name-server 210.205.2.52
!
interface Serial0
ip address 211.50.1.202 255.255.255.252
!
interface
Serial1
no ip address
shutdown
!
interface Serial2
no ip address
shutdown
!
interface Serial3
no ip address
shutdown
!
interface FastEthernet0
ip address 10.0.0.1
255.0.0.0
!
no ip classless
ip route 0.0.0.0 0.0.0.0 211.50.1.201
ip route 211.50.38.0 255.255.255.128
10.0.0.2
logging buffered informational
logging console informational
logging monitor informational
logging 211.50.38.2
snmp-server community wyzlab RO
snmp-server trap-authentication
banner
motd ^CWyzSoft Research & Development
Lab. Access-control Router^C
!
line con 0
line aux 0
line vty 0 4
password *******************
login
!
end
router#
|
-
¹æÈº® ¸®´ª½º ¹Ú½ºÀÇ ¼³Á¤
|
[root@bluebird
jhjung]# route
Kernel IP routing table
Destination Gateway
Genmask
Flags
Metric Ref
Use Iface
211.50.38.1 *
255.255.255.255
UH
0
0
0
eth0
10.0.0.2 *
255.255.255.255
UH
0
0
0
eth1
10.0.0.0 *
255.255.255.252
U
0
0
0
eth1
211.50.38.0 *
255.255.255.128
U
0
0
0
eth0
127.0.0.0 *
255.0.0.0
U
0
0
0
lo
default 10.0.0.1
0.0.0.0
UG
0
0
0
eth1
|
|
[root@unixian
/root]# traceroute linux.sarang.net
traceroute to linux.sarang.net (210.122.59.30),
30 hops max, 38 byte packets
1 211.50.38.1 (211.50.38.1)
0.241 ms 0.192 ms 0.149
ms
2 10.0.0.1 (10.0.0.1)
2.350 ms 0.884 ms 0.777
ms
3 211.50.1.201 (211.50.1.201)
4.102 ms 3.571 ms 3.443
ms
4 anybbb185-fe4-1-0.rt.bora.net
(210.120.252.102) 4.060 ms 3.680
ms 3.895 ms
5 anyg4-ge2-0.rt.bora.net
(210.120.193.145) 3.775 ms 3.728
ms 3.692 ms
6 selg2-pos8-0.rt.bora.net
(210.120.192.117) 4.423 ms 3.924
ms 3.943 ms
7 ysng12kix4-ge5-0.rt.bora.net
(210.120.192.69) 4.049 ms 4.053
ms 4.061 ms
8 210.107.53.66 (210.107.53.66)
4.911 ms 5.091 ms 5.216
ms
9 203.255.117.248 (203.255.117.248)
5.077 ms 5.759 ms 5.190
ms
10 10.241.1.178 (10.241.1.178)
12.136 ms 11.571 ms 11.424
ms
11 linux.sarang.net (210.122.59.30)
11.841 ms 10.977 ms 10.900
ms
|
|
[jhjung@www
jhjung]$ /usr/sbin/traceroute 211.50.38.38
traceroute to 211.50.38.38 (211.50.38.38),
30 hops max, 40 byte packets
1 210.118.74.1 (210.118.74.1)
2.944 ms 2.871 ms 2.908
ms
2 210.118.73.1 (210.118.73.1)
0.914 ms 0.905 ms 0.877
ms
3 210.118.49.97 (210.118.49.97)
3.146 ms 3.460 ms 2.889
ms
4 dacomkix-sds-s2-0.rt.bora.net
(203.233.37.221) 5.048 ms 5.653
ms 4.491 ms
5 selg2-ge5-0.rt.bora.net
(210.120.192.65) 4.608 ms 5.121
ms 4.654 ms
6 anyg4-pos8-0.rt.bora.net
(210.120.192.118) 5.543 ms 5.481
ms 4.817 ms
7 anybbb185-ge1-0-0.rt.bora.net
(210.120.193.147) 5.259 ms 69.667
ms 5.210 ms
8 anyaba74-fe1-0-0.rt.bora.net
(210.120.252.74) 5.457 ms 6.135
ms 5.139 ms
9 211.50.1.202 (211.50.1.202)
9.027 ms 9.660 ms 8.556
ms
10 10.0.0.2 (10.0.0.2)
8.838 ms 9.265 ms 8.908
ms
11 211.50.38.38 (211.50.38.38)
17.076 ms 8.672 ms 8.902
ms
|
5.
»ç¿ëÈıâ
¿ÜºÎ
³×Æ®¿÷ÀÌ T1À̱⠶§¹®¿¡ ¾ÆÁ÷ ÆøÁÖ¸¦ °æÇèÇØ º¸Áö´Â ¸øÇßÁö¸¸ »ó´çÈ÷ Æ÷¿öµù/¹æÈº®
¸Ó½®À¸·Î´Â °í»ç¾çÀ̱⠶§¹®¿¡ ÆÐŶ ·Î½ºÀ²ÀÌ °ÅÀÇ ¾øÀÌ Àß ÀÛµ¿ÇÑ´Ù. »ç½Ç
Æ÷¿öµù ÀÚü·Î´Â Àǹ̰¡ ¾ø°í ¹æÈº® ¼³ºñ¸¦ ¾ÆÁÖ ¿°°¡·Î ±¸ÃàÇÒ ¼ö ÀÖ±â
¶§¹®¿¡ »ç¶û¹Þ´Â °ü¸®ÀÚ°¡ µÉ ¼ö ÀÖÀ» °ÍÀÌ´Ù. Æ÷¿öµù ¸Ó½®¿¡¼ ³×Æ®¿öÅ©
ºÐ¼®Åø µéÀ» µ¹¸®¸é(IPtraf , ntop µî) ¸ðµç ³×Æ®¿÷À» °¨½ÃÇÒ
¼ö Àֱ⠶§¹®¿¡ °ü¸®°¡ ÇÑ°á ¼ö¿ùÇØÁø´Ù. ¾ÆÁ÷ ÇØ°áÇÏÁö ¸øÇÑ Á¡ÀÌ ÀÖ´Ù¸é
Æ÷¿öµù ¸Ó½® ÀÚü¿¡¼´Â ¿ÜºÎ ³×Æ®¿÷À¸·Î ¿¬°áÇÒ ¼ö°¡ ¾ø´Ù. ´Ù¸¥ PC¿¡¼
°¡Áö°í ³ª°¡´Â IP´Â ´ÜÁö Æ÷¿öµù¸¸ µÇ±â¶§¹®¿¡ »ó°ü¾øÁö¸¸ ½ÇÁ¦ Æ÷¿öµù ¸Ó½ÅÀÇ
±âº» IP°¡ 10.0.0.2·Î ³ª°¡±â ¶§¹®¿¡ ¿ÜºÎ·Î ¶ó¿ìÆÃ µÉ ¼ö ¾ø´Â
¹®Á¦ÀÎ°Í °°´Ù. IP tunnelingÀ» ¾²¸é °¡´ÉÇϰÚÁö¸¸ ¼öÀÍü°¨ÀÇ ¹ýÄ¢»ó
ÀÌ Á¤µµ´Â Å« ¹®Á¦°¡ ¾Æ´Ï±â ¶§¹®¿¡ Á׾ Æ÷¿öµù ¸Ó½®¿¡¼ ³×Æ®¿÷À» ½á¾ß°Ú´Ù´Â
ºÐÀº IP tunnell-ingÀ» ¿¬±¸ÇØ º¸±â ¹Ù¶õ´Ù. Âü°í·Î IPchains¸¦
½±°Ô ¼³Á¤ÇØ ÁÖ´Â µµ±¸´Â http://www.freshmeat.net ¿¡¼
ipchains·Î °Ë»ö ÇØº¸±â ¹Ù¶õ´Ù. º»ÀÎÀÌ °¡Àå Áñ°Ü ¾²´Â µµ±¸´Â gtkfront-endÀÎ
gfccÀÌ´Ù. ±×·³ Èí¿¬À» À§ÇØ À̸¸ ÁÙÀÔ´Ï´Ù.
6.
°¨»çÀÇ ¸»
-
³î·¯¿Ô´Ù°¡ ¿·¿¡¼ ¾öû³ª°Ô µµ¿òÀ» ÁØ ±èº´Âù(Àû¼ö)(redhands@linux.sarang.net)±º¿¡°Ô
¹«Áö °¨»çÇÔ.
- ¶ó¿ìÅÍ ¼³Á¤¿¡ ´ëÇÑ ¹«°øÀ» ÀüÇØÁֽŠÀÓäÇÊ(äÇø°) ´Ô¿¡°Ô °¨»çµå¸³´Ï´Ù.
- ¿·¿¡¼ ¹¬¹¬ÇÏ°Ô µµ¿ÍÁØ ¹Ú¹ü¼®(´ÙÄÜ), ÇãÀÎ(Çì·ÎÀÎ), ±è¿µÀÎ(ÆÄ¿öÀÚ¹Ù)
±º¿¡°Ô ¶ÇÇÑ °¨»ç.
|